plugin

Quadmenu Vulnerabilities

7 known security issues reported for the Quadmenu WordPress plugin. Most recent disclosed Apr 11, 2025.

1 critical 1 medium

Running Quadmenu on your site? Check whether your installed version is affected.

Scan your site free

WordPress Mega Menu – QuadMenu <= 3.2.0 - Cross-Site Request Forgery to Limited User Meta Update

medium

The WordPress Mega Menu – QuadMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the ajax_dismiss_notice() function. This makes it possible for unauthenticated attackers to update any user meta to a v...

CVSS:
4.3
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
Apr 11, 2025

CVE-2025-2871 on NVD →

QuadMenu &#8211; Mega Menu [quadmenu] < 2.0.7

unknown

[en] The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. This makes it possible for unauthenticated attackers to create arbitrary PHP files that can be used to execute malicious code.

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Oct 16, 2024

CVE-2021-4443 on NVD →

WordPress Mega Menu <= 2.0.6 - Arbitrary File Creation

critical

The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. This makes it possible for unauthenticated attackers to create arbitrary PHP files that can be used to execute malicious code.

CVSS:
9.8
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
Feb 22, 2021

CVE-2021-4443 on NVD →

QuadMenu &#8211; Mega Menu [quadmenu] < 2.0.7

unknown

Remote Code Execution (RCE) vulnerability found by Mikel Gorraiz in WordPress QuadMenu plugin (versions <= 2.0.6).

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Feb 22, 2021

QuadMenu &#8211; Mega Menu [quadmenu] < 2.0.7

unknown

The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. This makes it possible for unauthenticated attackers to create arbitrary PHP files that can be used to execute malicious code.

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Feb 22, 2021

QuadMenu &#8211; Mega Menu [quadmenu] < 2.0.7

unknown

The compiler_save AJAX action, available to both authenticated and unauthenticated users did not check the extension of the imported file, and had the nonce used for CSRF check displayed in the homepage. This could allow unauthenticated users to create an arbitrary PHP file on the blog, leading to RCE.

Affected:
up to 2.0.7
Fixed in:
2.0.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database